CVE-2024-13871: Bitdefender Box Firmware
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthenticated, network-adjacent attacker to execute arbitrary commands on the device, potentially leading to full remote code execution (RCE).
Affected products
- Bitdefender Box Firmware: version 1.3.11.490 only
Published 2025-03-12. Last modified 2026-06-17.